Security Enhancement System and Method for Machine-to-Card Binding Integrating Radio Frequency Fingerprint and PUF
By combining radio frequency fingerprinting and PUF technology, dynamic binding between the terminal and the SIM card is achieved, solving the problems of easy tampering of IMEI codes and insecure key storage, and improving the identity authentication security and device authentication accuracy of mobile communication systems.
Patent Information
- Application Number
- CN202510933206.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-08
- Publication Date
- 2025-11-14
- Estimated Expiration
- 2045-07-08
AI Technical Summary
Current mobile communication terminal authentication relies on queryable and easily tampered IMEI codes and static key storage, which makes SIM cards easy to clone and illegally bind, lacks dynamic and two-factor authentication, and has security vulnerabilities.
The device-SIM card binding security enhancement system, which integrates radio frequency fingerprinting and PUF, achieves two-factor binding between the terminal and SIM card by using radio frequency fingerprint features and PUF to generate dynamic keys through the collaborative work of the terminal and network sides, thus avoiding key storage and hardware cloning.
It improves the security and reliability of identity authentication, reduces the risk of key leakage, prevents unauthorized devices from accessing the system, and enhances the trustworthiness and robustness of the 5G industrial control system.
Smart Images

Figure CN120456022B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the fields of wireless communication and industrial control security technology, and relates to information security of 5G mobile communication in industrial control, and particularly to a device-card binding security enhancement system and method that integrates radio frequency fingerprinting and PUF. Background Technology
[0002] Currently, mobile communication terminal authentication primarily relies on the International Mobile Equipment Identity (IMEI) and the SIM card binding mechanism using the International Mobile Subscriber Identity / Subscription Permanent Identifier (IMSI / SUPI). The IMEI, as a terminal hardware identifier, is typically stored in the baseband chip or EEPROM. Its queryability and fixed storage characteristics make it vulnerable to cloning. Attackers can copy the IMEI by replacing the communication CPU, modifying the underlying data of the baseband memory, or tampering with flash memory information, thereby forging the terminal's identity. Statistics show that in 2022, global losses due to communication fraud caused by IMEI cloning exceeded $370 million.
[0003] Regarding user authentication, IMSI / SUPI and Ki keys are stored in the SIM card. Although the 5G standard uses 256-bit SUCI encryption, multiple security threats still exist: 1) Algorithm cracking risk: the development of quantum computing poses a challenge to traditional encryption; 2) Physical attack methods, including semi-intrusive attacks such as laser fault injection to extract keys. Experiments show that the Ki value of commercial SIM cards can be extracted within 72 hours using professional equipment; 3) Supply chain attacks: malicious firmware can steal key data from non-volatile memory. A GSMA report shows that SIM card cloning attacks increased by 42% year-on-year in 2021.
[0004] The existing solutions have fundamental flaws: (1) The static storage mechanism makes key identifiers easy to extract; tests show that 90% of Android device IMEIs can be read directly with root privileges; (2) The binding relationship depends on a copyable hardware identifier; a laboratory has successfully implemented real-time IMEI tampering based on FPGA; (3) Key storage lacks dynamism; the Ki value of a traditional SIM card cannot be updated after being written. Although the 3GPP TS33.501 standard introduces the SUPI protection mechanism, it does not solve the problem of identity forgery at the terminal hardware level.
[0005] Radio frequency (RF) fingerprinting offers a new approach to solving the aforementioned problems. By analyzing subtle features of the terminal's wireless signal (including carrier frequency offset, phase noise, I / Q imbalance, etc.) to identify the device, it has two core advantages: 1) Physical non-cloning, with RF characteristics of terminals of the same model differing by 0.5-3dB; 2) Dynamic acquisition characteristics, eliminating the need to store feature data on the terminal.
[0006] Physically Unclonable Functions (PUFs) enhance security at the hardware level: 1) They utilize differences in semiconductor manufacturing to generate unique responses, with the response repetition rate of PUF chips on the same wafer being <10. -6 2) The challenge-response mechanism avoids key storage. NIST tests show that the keys generated by PUF are 20 times more resistant to side-channel attacks. However, existing PUF applications are mostly limited to single-device authentication and have not yet been deeply integrated with the identity system of communication systems.
[0007] There is an urgent need in this field for a new authentication system that integrates radio frequency fingerprinting and PUF, which requires overcoming three major bottlenecks:
[0008] 1) Real-time extraction and digital encoding of radio frequency features;
[0009] 2) Establish a collaborative working mechanism between the terminal PUF and the SIM card PUF;
[0010] 3) Design a network-side dynamic binding architecture to be compatible with the existing 5G core network.
[0011] Solving these problems will fundamentally change the security paradigm of mobile communication identity authentication.
[0012] In existing industrial control 5G mobile communication systems, SIM cards are typically not paired and bound to fixed mobile terminals. Currently, wireless industrial control terminals widely use SIM cards for authentication and communication, especially in 5G mobile communication systems where the SIM card serves as a core security component for terminal network access. Therefore, users can access the 5G communication network regardless of whether they change their mobile phone or other communication terminal, use an old SIM card, replace the SIM card, or use an old communication terminal. However, SIM card authentication relies on a single-factor authentication mechanism, based solely on a pre-stored key or certificate on the card. This makes it vulnerable to cloning or unauthorized insertion into unauthorized devices, leading to risks of unauthorized access and data leakage. If attackers physically steal or use software attacks to copy SIM card information and use it in unauthorized terminals, especially in industrial control scenarios, it could cause equipment operation or production interruptions.
[0013] For users with high security needs in certain specialized fields, SIM card binding establishes a fixed correspondence between the SIM card and a specific terminal device. On one hand, if the SIM card is illegally removed and attempted to be used in another terminal, the system will restrict its communication functions, effectively preventing SIM card misuse or theft. On the other hand, after binding, data transmission between the terminal device and the SIM card is more secure because unauthorized devices cannot access the network, thus reducing the risk of data leakage. Existing SIM card binding technologies include mapping the SIM card to the operating system or application software. A more common method is to bind the SIM card to a specific terminal device by mapping the terminal device's unique identifier (International Mobile Equipment Identity, IMEI), International Mobile Subscriber Identity (IMSI), or Subscription Permanent Identity (SUPI) – which is the SIM card's unique identifier. Existing technology, a method for verifying the binding relationship between SUPI and IMEI, includes: obtaining a list of SUPI and IMEI relationships; if the target SUPI of the terminal is verified to be valid, obtaining the target IMEI of the terminal; and completing the binding verification of the target SUPI and the target IMEI based on the list of SUPI and IMEI relationships.
[0014] Existing systems lack an effective SIM card binding mechanism, resulting in a weak association between the SIM card and the terminal device, failing to ensure that the card is used only for legitimate devices. This is because traditional methods rely on static identifiers such as IMEI codes, which are easily tampered with or forged. Furthermore, key management is weak; private keys are often stored long-term on the SIM card or in the terminal's memory, making them vulnerable to side-channel attacks or malware extraction. Analysis shows that approximately 30% of security incidents stem from key leaks. Finally, while RFID fingerprinting technology is used for device identification, it is not integrated with SIM card authentication, failing to achieve two-factor authentication and resulting in overall insufficient security. The root cause of these problems lies in the simplistic technical architecture, which fails to integrate dynamic key generation and physical layer signature authentication.
[0015] The IMEI code of existing terminals is queryable and part of the terminal hardware, typically stored in the phone's baseband or electrically erasable programmable read-only memory (EEPROM). It can be copied or cloned using specific techniques, such as replacing the communication CPU, altering the underlying data of the baseband memory, and modifying device information in the flash memory. The IMSI / SUPI, however, is stored in the SIM card. The SIM card itself contains key values such as the IMSI, Integrated Circuit Card Identity (ICCID), and Key Identifier (Ki). Because the Ki is encrypted and unique, although copying a SIM card is difficult in 5G communication systems, attackers can still obtain the key from non-volatile memory using various techniques, such as cracking encryption algorithms, side-channel attacks, invasive or semi-invasive attacks, and Trojan implantation. Therefore, using IMSI / SUPI and IMEI for verifying the device-SIM card binding relationship poses certain security risks. There is an urgent need to improve this method by leveraging the uniqueness, permanence, and remote identifiability of radio frequency fingerprints. Summary of the Invention
[0016] The purpose of this invention is to address the security risks inherent in existing verification methods that use IMSI / SUPI and IMEI for SIM card binding. These methods allow for the replication of 5G communication SIM cards by obtaining keys through means such as cracking encryption algorithms, side-channel attacks, intrusive and semi-intrusive attacks, and Trojan horse implantation. Therefore, there is an urgent need to improve the security of SIM card binding by integrating RF fingerprints and PUF, which are unique, permanent, and remotely identifiable.
[0017] To achieve the above objectives, the present invention adopts the following technical solution.
[0018] Firstly, a device-SIM card binding security enhancement system integrating radio frequency fingerprinting and PUF is proposed, comprising a terminal-side device and a network-side device deployed at the air interface of a 5G mobile communication system. Both the terminal-side device and the network-side device include a wireless function processing module for performing functional processing of the wireless communication protocol stack corresponding to the wireless security communication system, including radio frequency, baseband, and upper-layer protocol stack processing. The system also includes a SIM card and its interaction processing module, with the SIM card on the terminal side including a PUF processing module and a password and data processing forwarding module. The network-side device includes a base station and a core network, with the core network internally or externally adding a radio frequency fingerprint processing module, a password and data processing forwarding module, and functional modules. The radio frequency fingerprint processing module performs secondary authentication of the terminal on the network side based on radio frequency fingerprint identity feature information.
[0019] Preferably, the wireless function processing module of the terminal device receives the wireless signal and performs radio frequency, baseband and upper layer protocol stack processing, while the wireless function processing module of the network device simultaneously collects the IQ data after analog-to-digital conversion and distributes it according to the instructions of the radio frequency fingerprint processing module.
[0020] The terminal-side device also includes a SIM card and its interaction processing module. The SIM card includes a PUF processing module and a terminal-side password and data processing and forwarding module. After the terminal-side device obtains the terminal's special identification code, the PUF processing module uses the identification code as a challenge input to generate a private key. The private key is regenerated each time and deleted after use.
[0021] Preferably, the PUF processing module generates a truly random signal sequence as the private key, enhancing the unpredictability of the key; the network-side cryptography and data processing forwarding module dynamically updates the mapping relationship after authentication, improving the binding flexibility.
[0022] The network-side device implements secondary identity authentication for the terminal based on radio frequency fingerprint identity feature information, and binds the terminal's special identity identification code with the SIM card's special identity identification code.
[0023] Preferably, the radio frequency fingerprint processing module is configured with a radio frequency fingerprint enable switch, which, when enabled, instructs the wireless function module to control the multiple distribution of IQ data.
[0024] Furthermore, the aforementioned secondary authentication of the terminal is specifically implemented on the network side by the radio frequency fingerprint processing module based on the radio frequency fingerprint identity feature information; and after the secondary authentication, the password and data processing and forwarding module uses the radio frequency fingerprint identity feature information as a special identity identification code for the terminal in a one-time password form, without storing the identification code for a long time.
[0025] Furthermore, the radio frequency fingerprint processing module extracts radio frequency fingerprint feature values based on IQ data, which are used as unique identifiers for secondary authentication. Combined with the special identity identification code of the terminal generated by the PUF processing module, i.e., the fingerprint feature information of the SIM card chip, two-factor SIM card binding is achieved.
[0026] Furthermore, the terminal-side device also generates a private key through the PUF processing module of the SIM card, which is regenerated through PUF each time it is used and deleted after use.
[0027] Furthermore, after receiving the wireless signal from the other end, the wireless function processing module of the terminal-side device and the network-side device performs functional processing of the wireless communication protocol stack corresponding to the wireless security communication system, including radio frequency, baseband and upper layer protocol stack processing. At the same time, the network side collects the IQ data after analog-to-digital conversion and sends it to the radio frequency fingerprint processing module according to the instruction of the radio frequency fingerprint processing module.
[0028] Preferably, after the terminal-side device obtains the terminal's special identification code, the SIM card and its interaction processing module use the terminal's special identification code as the input challenge information for the PUF processing module, and use the output response information generated by the PUF as the SIM card's special identification code.
[0029] The network-side device maps and binds the currently generated terminal special identification code and SIM card special identification code to achieve device-card binding.
[0030] Furthermore, the radio frequency fingerprint processing module of the network-side device is used to generate IQ data sampling indication, send it to the wireless function processing module for handshaking, receive IQ data sent by the wireless function processing module, use the IQ data for training to extract the radio frequency fingerprint of the peer device, compare the processing result with the radio frequency fingerprint feature library inside the module, and send the comparison result to the core network or the application server for secondary authentication. The radio frequency fingerprint feature value is used as the unique identification feature information of the terminal bound to the SIM card for corresponding processing.
[0031] Furthermore, the PUF processing module in the terminal-side device is used to generate a terminal-side private key, using a random number as PUF challenge information. The PUF processing module obtains the PUF challenge information, generates a true random signal sequence based on the random deviation of the internal circuit characteristics, and outputs PUF response information as the terminal-side private key. The private key is not stored during the process and is regenerated each time it is used. In addition, the PUF processing module is used to generate the chip fingerprint feature information of the SIM card as the unique identification feature information of the SIM card bound to the device.
[0032] Preferably, after obtaining the terminal's special identification code, the terminal-side device uses the identification code to generate a private key through the Physically Unclonable Function (PUF) of the SIM card;
[0033] Preferably, the RF fingerprint feature is not stored locally on the terminal, but is only transmitted to the SIM card PUF module as temporary challenge information to prevent extraction or tampering. The network-side device continuously updates the RF fingerprint template through machine learning algorithms to adapt to feature drift caused by terminal hardware aging or environmental changes. The PUF processing module deeply couples PUF with key management: the SIM card PUF module adopts a multi-level challenge-response mechanism: the first level input is the RF fingerprint feature, and the second level input is a random number issued by the network-side device to ensure the uniqueness of each response. The generated PUF response serves as both an identity identifier and a seed for the elliptic curve cryptography (ECC) private key, achieving "one feature, one key".
[0034] Preferably, the communication between the terminal device and the network device uses session key encryption derived from the PUF response to prevent man-in-the-middle attacks; the SIM card PUF module has a side-channel attack resistance design, such as adding noise masking or timing randomization; fault tolerance mechanism: when the RF fingerprint fails to match due to signal interference, a backup authentication process based on the PUF response is activated, and historical binding relationships are used to assist in verification;
[0035] The RF fingerprint extracted by the terminal device uses compressed sensing to reduce computational overhead; the SIM card PUF module adopts a lightweight PUF architecture based on SRAM, which is compatible with existing SIM card chip technology; the network-side device's RF fingerprint engine supports 3G / 4G / 5G multi-standard signal analysis and is adapted to heterogeneous network environments; the binding relationship database is designed with a distributed architecture, which can be seamlessly integrated with existing unified data management UDM network elements;
[0036] Registration phase: 1. When the terminal first enters the network, the network-side device collects its radio frequency fingerprint and generates a feature template; 2. The terminal sends the radio frequency fingerprint feature to the SIM card PUF module, generates an initial response, and uploads it to the network side for binding;
[0037] Authentication Phase: 1. The terminal initiates a connection request, and the network-side device extracts its radio frequency fingerprint in real time for Level 1 authentication; 2. After successful authentication, the network-side device sends a random challenge to the SIM card PUF module to verify whether the response matches the binding relationship; 3. The session key is dynamically generated from the PUF response, completing the establishment of a secure channel;
[0038] Synergistic relationship between technical features: The uniqueness of RF fingerprints and the non-cloning nature of PUF complement each other: the former solves the problem of terminal identity forgery, and the latter solves the problem of SIM card duplication; the dynamic key mechanism relies on the randomness of PUF, while the challenge input of PUF module relies on the stability of RF fingerprint, forming a closed-loop security chain;
[0039] As a second aspect of the present invention, a device-SIM card binding security enhancement method integrating radio frequency fingerprint and PUF is proposed, relying on the terminal side and the network side, both of which include radio frequency, baseband and upper layer protocol stack processing; after obtaining the terminal's special identification code, the terminal side uses the identification code as a challenge input to generate a private key, and the private key is regenerated each time and deleted after use; the network side implements secondary identity authentication on the terminal side based on the radio frequency fingerprint identity feature information, and binds the terminal's special identification code and the SIM card's special identification code;
[0040] Furthermore, the secondary authentication is specifically implemented on the network side based on radio frequency fingerprint identity feature information; and after the secondary authentication, the radio frequency fingerprint identity feature information is used as a special identity identification code for the terminal in a one-time password form, and the identification code is not stored for a long time.
[0041] Furthermore, the radio frequency fingerprint identity feature information is a radio frequency fingerprint feature value extracted based on IQ data, which serves as a unique identifier on the terminal side for secondary authentication. The terminal special identity identification code generated by PUF, i.e., the SIM card chip fingerprint feature information, realizes two-factor SIM card binding.
[0042] Furthermore, after obtaining the terminal's special identification code, the terminal side uses this special identification code as the challenge information input to the PUF, and the output response information generated by the PUF is used as the SIM card's special identification code; the network side binds the currently generated terminal special identification code and SIM card special identification code through a mapping relationship to achieve device-card binding.
[0043] Beneficial effects
[0044] The SIM card binding security enhancement system and method integrating radio frequency fingerprinting and PUF proposed in this invention have the following advantages compared with the prior art:
[0045] 1. The method utilizes the uniqueness, permanence, and remote identification capabilities of radio frequency fingerprints. Based on the use of radio frequency fingerprint identity feature information as a special identification code for the terminal, the network side maps and binds the generated special identification code for the terminal and the special identification code for the SIM card. Compared with existing technologies, this achieves a strong binding function between the terminal and the SIM card, i.e., secondary authentication of the terminal on the network side.
[0046] 2. The system avoids attackers obtaining the terminal's unique identification code from non-volatile memory by not storing it in the terminal for extended periods;
[0047] 3. After the terminal of the system obtains the terminal's special identification code, it uses the terminal's special identification code as the input challenge information of the Physically Unclonable Function (PUF) of the SIM card to generate a private key and other output response information as the SIM card's special identification code. The private key is generated by the PUF function and does not need to be stored locally. It is easy to use a one-time key and is regenerated by the PUF each time it is used. It is deleted after use, so that attackers cannot obtain the key and improve the overall security. Attached Figure Description
[0048] Figure 1 This invention describes the internal unit composition and connection relationship of the RF fingerprint module in the SIM card binding security enhancement system that integrates RF fingerprint and PUF.
[0049] Figure 2 This is a schematic diagram of the wireless function processing module in the SIM card binding security enhancement system integrating radio frequency fingerprint and PUF of the present invention;
[0050] Figure 3A schematic diagram of the internal unit of the key and data processing and forwarding module in the SIM card binding security enhancement system integrating radio frequency fingerprinting and PUF of this invention;
[0051] Figure 4 This is a schematic diagram of the terminal-side system and device in the SIM card binding security enhancement system that integrates radio frequency fingerprinting and PUF according to the present invention;
[0052] Figure 5 This is a schematic diagram of the network-side system and device in the SIM card binding security enhancement system that integrates radio frequency fingerprinting and PUF according to the present invention;
[0053] Figure 6 This is a schematic diagram of the main authentication process for a device-card binding security enhancement method that integrates radio frequency fingerprinting and PUF;
[0054] Figure 7 This is a flowchart of the overall solution for a device-card binding security enhancement method that integrates radio frequency fingerprinting and PUF. Detailed Implementation
[0055] The technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are some embodiments of the present invention, but not all embodiments.
[0056] The core technical problem addressed in this application is preventing unauthorized access and data security risks caused by the insertion of SIM cards into unauthorized wireless industrial control terminals. Specifically, this includes the ease with which single-factor authentication can be bypassed, key storage leakage, and the lack of a strong binding mechanism between the device and the SIM card. Compared to existing technologies, the application achieves the following advantages: by using the terminal's radio frequency fingerprint as a dynamic identity identifier, combined with the response information generated by the SIM card's PUF module, a non-replicable two-way authentication system is constructed, completely resolving the cloning risk of traditional IMEI / IMSI binding methods, including:
[0057] By dynamically generating private keys using PUF (regenerated each time and deleted after use), the risk of key storage is eliminated, and experimental simulations show that the probability of key leakage is reduced to below 0.1%. Combined with RF fingerprint secondary authentication, a two-factor authentication mechanism is implemented, and tests show that the success rate of unauthorized access has decreased from the current 20% to less than 1%, while the authentication accuracy has increased to 99.5%. SIM card binding based on RF fingerprint features and PUF-generated SIM card fingerprints ensures that the SIM card is used only for legitimate terminals, reducing device cloning attacks in industrial scenarios by 90%. Economically, it reduces downtime losses caused by security incidents, with estimated annual cost savings in the millions. Socially, it enhances the trustworthiness of 5G industrial control systems and promotes secure IoT deployment. Overall, the system robustness is improved; the IQ data training of the RF fingerprint processing module reduces the feature extraction error rate to less than 0.5%.
[0058] The system includes terminal-side devices and network-side devices deployed at the air interface of a 5G mobile communication system. Both the terminal-side and network-side devices include a wireless function processing module for processing the corresponding wireless communication protocol stack of the wireless security communication system, including radio frequency, baseband, and upper-layer protocol stack processing. The system also includes a SIM card and its interaction processing module. The SIM card on the terminal side includes a PUF processing module and a password and data processing forwarding module. The network-side devices include a base station and a core network. An radio frequency fingerprint processing module, a password and data processing forwarding module, and functional modules are added internally or externally to the core network. The radio frequency fingerprint processing module performs secondary authentication of the terminal on the network side based on radio frequency fingerprint identity feature information. The internal unit composition and connection relationship of the radio frequency fingerprint module are as follows: Figure 1 As shown.
[0059] Preferably, the wireless function processing module of the terminal-side device receives the wireless signal and performs radio frequency, baseband, and upper-layer protocol stack processing. Simultaneously, the wireless function processing module of the network-side device collects the analog-to-digital converted IQ data and distributes it according to the instructions of the radio frequency fingerprint processing module. A schematic diagram of the wireless function processing module is shown below. Figure 2 As shown;
[0060] The terminal-side device also includes a SIM card and its interaction processing module. The SIM card includes a PUF processing module and a terminal-side password and data processing and forwarding module. After the terminal-side device obtains the terminal's special identification code, the PUF processing module uses the identification code as a challenge input to generate a private key. The private key is regenerated each time and deleted after use.
[0061] Preferably, the PUF processing module generates a truly random signal sequence as the private key, enhancing the unpredictability of the key; the network-side cryptography and data processing forwarding module dynamically updates the mapping relationship after authentication, improving the binding flexibility.
[0062] The network-side device implements secondary identity authentication for the terminal based on radio frequency fingerprint identity feature information, and binds the terminal's special identity identification code with the SIM card's special identity identification code.
[0063] Preferably, the radio frequency fingerprint processing module is configured with a radio frequency fingerprint enable switch, which, when enabled, instructs the wireless function module to control the multiple distribution of IQ data.
[0064] The core of this application lies in the synergistic application of radio frequency fingerprinting technology and physically unclonable functions (PUFs) to completely reconstruct the SIM card binding mechanism in 5G communication systems, thereby resolving security vulnerabilities such as hardware cloning and key theft in existing IMEI / IMSI binding schemes. The following details its effects from technical, economic, and social perspectives:
[0065] The introduction of radio frequency (RF) fingerprinting upgrades terminal authentication from "tamperable hardware identifiers" to "uncopyable physical features." Experimental data shows that the recognition accuracy based on RF fingerprints (such as carrier frequency offset and phase noise features) can exceed 95% (IEEE Transactions on Information Forensics and Security, 2021), and attackers cannot simulate hardware-level RF feature differences through software means.
[0066] The response information generated by the PUF module serves as the SIM card identification code. Combined with the "one-time key" mechanism, the key lifecycle is shortened to a single communication session. Tests show that compared to traditional Ki key storage schemes, the PUF dynamic key's resistance to side-channel attacks is significantly improved (referencing the NIST SP800-22 randomness test standard). The terminal's special identification code (RF fingerprint feature) is only temporarily generated and mapped on the network side, with no persistent storage in either the terminal or the SIM card. Penetration testing has verified that this design can resist 99.7% of non-volatile memory extraction attacks (including physical attack methods such as JTAG debugging and chip grinding).
[0067] 1) Enhanced Privacy Protection: By eliminating the storage of permanent device identifiers such as IMEI, the difficulty of tracing user devices is significantly increased. Following an EU GDPR compliance assessment, this solution can reduce the risk level of personal data breaches from "high risk" to "acceptable."
[0068] 2) IoT Security Enhancement: For scenarios such as connected vehicles and industrial IoT, the solution provides a dynamic binding mechanism to prevent device spoofing. Tests show that in V2X communication, the detection rate of spoofed terminals is increased from 89% in traditional solutions to 99.6%, with a latency increase of only 2.3ms (meeting 3GPP URLLC requirements).
[0069] The comparative experimental data in a 5G NSA network environment, compared with the traditional solution, are as follows:
[0070] Anti-cloning attack success rate: Traditional methods have a success rate of 34% (based on IMEI tampering), while this method has a success rate of 0.02%.
[0071] Key leakage response time: Traditional solutions require an average of 72 hours to revoke a key, while this solution can achieve real-time invalidation due to its dynamic generation feature;
[0072] System overhead: The addition of the RF fingerprint processing module only increases the CPU load of the core network by 0.8%, while the wireless air interface signaling overhead increases by 1.2%.
[0073] This application constructs a full-stack security protection system from the physical layer to the application layer by leveraging the dual non-cloning characteristics of "RF fingerprint + PUF". Its technical indicators are significantly better than the 5G security baseline requirements specified in 3GPP TS33.501.
[0074] Furthermore, after the aforementioned secondary authentication, the password and data processing forwarding module uses the radio frequency fingerprint identity feature information as the terminal's special identification code, which does not need to be stored locally and is generated in a one-time password format. The terminal's special identification code is not stored on the terminal for a long time, thus preventing attackers from obtaining the terminal's special identification code from non-volatile memory.
[0075] Furthermore, after the terminal obtains the terminal's special identification code, the SIM card and its interaction processing module use the terminal's special identification code as the input challenge information for the PUF processing module, and use the output response information generated by the PUF as the SIM card's special identification code.
[0076] Furthermore, the terminal special identification code and SIM card special identification code generated in the aforementioned network-side device are mapped and bound together to achieve device-SIM card binding.
[0077] Furthermore, the terminal of the aforementioned terminal-side device also generates a private key through the PUF processing module of the SIM card. The key is regenerated through the PUF each time it is used and deleted after use, making it impossible for attackers to obtain the key and improving overall security.
[0078] Furthermore, the wireless function processing modules of the aforementioned terminal-side device and network-side device, after receiving the wireless signal from the other end, perform functional processing of the wireless communication protocol stack corresponding to the wireless security communication system, including radio frequency, baseband and upper layer protocol stack processing. At the same time, the network side collects the IQ data after analog-to-digital conversion and sends it to the radio frequency fingerprint processing module according to the instruction of the radio frequency fingerprint processing module.
[0079] Furthermore, the aforementioned RF fingerprint processing module is equipped with an RF fingerprint enable switch. When enabled, it instructs the wireless function module to distribute the IQ data through an additional channel.
[0080] Furthermore, the radio frequency fingerprint processing module of the aforementioned network-side device is used to generate IQ data sampling indication, send it to the wireless function processing module for handshaking, receive the IQ data sent by the wireless function processing module, use the IQ data for training to extract the radio frequency fingerprint of the peer device, compare the processing result with the radio frequency fingerprint feature library inside the module, and send the comparison result to the core network or the application server for secondary authentication. The radio frequency fingerprint feature value is used as the unique identification feature information of the terminal bound to the SIM card for corresponding processing.
[0081] Furthermore, the PUF processing module in the aforementioned terminal-side device is used to generate a terminal-side private key, using a random number as the PUF challenge information. The PUF processing module obtains the PUF challenge information, generates a true random signal sequence based on the random deviation of the internal circuit characteristics, and outputs PUF response information as the terminal-side private key. The private key is not stored during the process and is regenerated each time it is used. In addition, the PUF processing module is used to generate the chip fingerprint feature information of the SIM card as the unique identification feature information of the SIM card bound to the device.
[0082] The terminal-side device also includes a SIM card and its interaction processing module. The SIM card includes a PUF processing module and a terminal-side password and data processing and forwarding module. After the terminal-side device obtains the terminal's special identification code, the PUF processing module uses the identification code as a challenge input to generate a private key. The private key is regenerated each time and deleted after use.
[0083] In practical implementation, the terminal-side device also includes an RF fingerprint acquisition module, used to analyze the inherent characteristics of the terminal's wireless signal (such as carrier frequency offset, phase noise, etc.) to generate unique identity features; a PUF processing module, integrated into the SIM card, receives the RF fingerprint features as challenge input and generates unpredictable response output. A dynamic key generation module generates a temporary private key in real time based on the PUF response, which is deleted after use and not stored in non-volatile memory; the network-side device identifies the RF fingerprint and deploys it in the core network or base station, extracts the terminal signal features and matches them with pre-stored templates; it stores the dynamic binding relationship between the terminal-side device's RF fingerprint features and the SIM card's PUF response, forming a mapping database; after verifying the terminal's RF fingerprint in the network-side device, it triggers the SIM card's PUF response verification, achieving dual verification.
[0084] The terminal-side cryptographic and data processing forwarding module and the network-side cryptographic and data processing forwarding module are collectively referred to as the key and data processing forwarding module, as illustrated below. Figure 3 As shown in Table 1, the Chinese terms and their English terms and abbreviations involved in this application are described in Table 1 and will not be repeated here.
[0085] Table 1. Abbreviations in Chinese and English used in this application
[0086]
[0087] Example 1
[0088] This invention provides a system for preventing the insertion of SIM cards into unauthorized wireless industrial control terminals, comprising a terminal-side device and a network-side device deployed at the air interface of a 5G mobile communication system, such as... Figure 4 and Figure 5As shown, both the terminal-side device and the network-side device include a wireless function processing module for processing the wireless communication protocol stack corresponding to the wireless security communication system, including radio frequency, baseband, and upper-layer protocol stack processing. The terminal-side device includes a SIM card and its interaction processing module. The SIM card on the terminal side includes a PUF processing module and a password and data processing forwarding module. The network-side device includes a base station and a core network. An radio frequency fingerprint processing module, a password and data processing forwarding module, and functional modules are added internally or externally to the core network. The radio frequency fingerprint processing module performs secondary authentication of the terminal on the network side based on radio frequency fingerprint identity feature information.
[0089] like Figure 1 As shown, the radio frequency fingerprint module consists of important internal units such as a feature extraction unit, a recognition and analysis unit, and a machine learning unit. The functions of each unit are as follows:
[0090] The feature extraction unit is responsible for analyzing and extracting features from the raw signal data, providing crucial data for subsequent signal recognition and analysis. The quality of feature extraction directly affects the system's accuracy and efficiency in signal recognition. First, signal preprocessing is performed, including denoising, filtering, and normalization, to reduce noise impact and improve signal quality. Then, the raw signal data is analyzed, and a suitable feature extraction algorithm is selected to extract multi-dimensional signal features. In practice, these multi-dimensional features should include at least 20 dimensions, including frequency domain features, time domain features, and statistical features. The extracted feature data is stored in a feature database for use by the subsequent recognition and analysis module. The storage scheme needs to consider efficient data access and security.
[0091] The identification and analysis unit utilizes the feature data obtained from the feature extraction module to classify and identify signals through machine learning, determining which device or specific category they belong to. The identification module plays a crucial role in the entire system, providing users with fundamental information for signal identification and analysis. The identification module receives feature data from the feature extraction module, which undergoes preprocessing and dimensionality reduction by the preprocessing unit to prepare it as input for the identification algorithm. Machine learning algorithms are then implemented to train the model on the feature data. This includes model construction, parameter tuning, and optimization to improve the accuracy and performance of the identification model. The trained model is then used to classify and identify new feature data, determining which device or specific category the signal originates from. The identification results are output in structured data format, including device information, signal classification, and possible signal sources, allowing users to intuitively understand the results.
[0092] The machine learning unit is responsible for training and applying various machine learning models, including five types: K-Nearest Neighbors (KNN), Support Vector Machines (SVM), Random Forest, Decision Trees, and Naive Bayes. This module trains models based on extracted feature data and uses the trained models to classify and recognize new data. Specifically, it involves: selecting commonly used machine learning libraries such as scikit-learn, TensorFlow, and PyTorch for model training and application; preparing training and test sets by dividing the feature data into training and test sets for model training and validation; model building and training by constructing the selected model and training it using the training set, adjusting model parameters for optimal performance; model evaluation and optimization by evaluating model performance using the test set and optimizing model parameters and structure to obtain models with high accuracy and generalization ability; implementing model selection algorithms such as cross-validation and grid search to help users choose the best model and parameters; providing model comparison and contrast functions to evaluate and select the performance of different models; and saving the trained model to the file system for later loading and use.
[0093] Both the terminal-side device and the network-side device include a wireless function processing module, which is used to perform functional processing of the wireless communication protocol stack corresponding to the wireless security communication system, including radio frequency, baseband and upper layer protocol stack processing. Figure 2 The diagram illustrates the composition of the wireless function processing module. On the terminal side, this module is primarily implemented within the terminal chip. On the network side, it is mainly implemented within the base station, with the core network implementing 3GPP standard core network functions. Upon receiving the wireless signal from the peer, the wireless function processing module performs functional processing corresponding to the wireless communication protocol stack of the wireless security communication system, including radio frequency (RF), baseband, and upper-layer protocol stack processing. Simultaneously, the network side collects the analog-to-digital converted IQ data and sends it to the RF fingerprint processing module according to its instructions.
[0094] The Physical Unclonable Function (PUF) on the terminal side is a cryptographic technique that generates unique identifiers based on the physical characteristics of hardware, often referred to as "chip fingerprinting." Its core idea is to utilize unavoidable microscopic physical differences during manufacturing (such as transistor threshold voltage deviations and metal linewidth fluctuations) as a natural source of entropy to generate a device-specific digital fingerprint.
[0095] A Programmable Array (PUF) triggers a response from the chip's internal physical structure by taking a challenge as input, outputting a unique response. For example, differences in transistor threshold voltage during manufacturing can lead to different initial values for SRAM cells upon power-up (SRAM PUF); differences in signal propagation delay in circuit paths can form the basis for the response of a delayed PUF (such as an arbitrator PUF); differences in the optical reflection properties of microscopic wrinkles on material surfaces can construct optical PUFs, etc. Key characteristics of PUFs include: uniqueness (different chips respond significantly differently to the same challenge); non-cloning (even if an attacker obtains the chip design, they cannot replicate the same physical characteristics (due to uncontrollable process deviations); stability (the same chip can still output a consistent response under temperature changes and voltage fluctuations); and randomness (the entropy value of the response bit is close to the theoretical maximum, meeting cryptographic security requirements).
[0096] The network side maps and binds the generated terminal special identification code and SIM card special identification code to realize the device-card binding function. In addition, the terminal also generates a private key through the SIM card's Physically Unclonable Function (PUF). This key does not need to be stored locally and is easy to use with one-time passwords. It is regenerated through the PUF each time it is used and deleted after use, making it impossible for attackers to obtain the key and improving overall security.
[0097] In specific implementation, the functional modules of the network-side device are located in, but are not limited to, a network element such as the UDM or AMF of the core network, the core network management platform, and the application server after the N6 core network.
[0098] The radio frequency fingerprint processing module is used to generate IQ data sampling indications, send them to the wireless function processing module for handshaking, receive IQ data sent by the wireless function processing module, use the IQ data for training to extract the radio frequency fingerprint of the peer device, compare the processing results with the radio frequency fingerprint feature library inside the module, and send the comparison results to the core network or the application server for secondary authentication. The radio frequency fingerprint feature value is used as the unique identification feature information of the terminal bound to the SIM card for corresponding processing.
[0099] The PUF processing module is used to generate the terminal-side private key. It uses a random number as the PUF challenge information. The PUF processing module obtains the PUF challenge information and generates a true random signal sequence based on the random deviation of the internal circuit characteristics. It outputs the PUF response information as the terminal-side private key. The private key is not stored during the process and is regenerated each time it is used. In addition, the PUF processing module generates the chip fingerprint feature information of the SIM card as the unique identification feature information of the SIM card bound to the device.
[0100] Internal units of the wireless function processing module, such as Figure 1 As shown:
[0101] This invention also provides a method for preventing the unauthorized insertion of a SIM card into a wireless industrial control terminal. Specifically, it employs radio frequency fingerprinting for secondary authentication. After secondary authentication of the terminal via radio frequency fingerprinting on the network side, the RF fingerprint's identity feature information is used as a unique identifier for the terminal. This unique identifier is not permanently stored in the terminal to prevent attackers from retrieving it from non-volatile memory. After obtaining the unique identifier, the terminal uses it as the input challenge information for the Physical Unclonable Function (PUF) module of the SIM card. The output response information generated by the PUF is then used as the unique identifier for the SIM card. The specific steps are as follows:
[0102] Step 1: One-time authentication (5G user master authentication and two-way authentication);
[0103] Due to the lack of a unified security authentication system in 4G and earlier networks, fake base stations could attract user terminals by increasing signal transmission power, stealing user data. Terminals could not accurately determine the legitimacy of the network. When a 5G user equipment (UE) accesses the network, a symmetric algorithm is used for primary authentication with the core network element (Unified Data Management, UDM) during the network access process, preventing the UE from accessing fake base stations or impersonating networks. Based on the 5G key system, terminal-network two-way authentication allows the terminal and network to mutually authenticate each other, ensuring the legitimacy of both parties' identities. This includes authentication of the terminal user by the 5G network side and authentication of the network side by the terminal user.
[0104] 5G uses a root key K to implement key derivation and hierarchical management during network data transmission encryption and integrity protection, constructing a security context and preventing unauthorized terminals or base stations from accessing the 5G network. Both the terminal and the core network possess a root key K value, and then generate their respective key parameters based on K and a key derivation algorithm during signaling interaction. During initial registration, the terminal and the network calculate a MAC value and a RES* value, respectively. The MAC value is used for terminal authentication by comparing the locally calculated MAC value with the MAC value transmitted from the network to the terminal to determine network security. The RES* value is used by the network to authenticate the terminal by comparing the locally calculated RES* value to determine the terminal's legitimacy. This two-way authentication effectively avoids the problem of fake base stations. The specific main authentication process and steps are as follows: Figure 6 As shown, it includes:
[0105] S31. For each Nudm_Authenticate_Get request, UDM / ARPF creates a 5G HE AV. Then UDM / ARPF derives XRES*, and finally creates the 5G HE AV (RAND, AUTN, XRES*).
[0106] S32, UDM / ARPF sends 5G HE AV (RAND, AUTN, XRES*) to AUSF in the Nudm_Authenticate_Get response. If SUCI is included in the Nudm_Authenticate_Get request message, then UDM / ARPF also carries the parameter SUPI in the Nudm_Authenticate_Get response;
[0107] S33. AUSF should temporarily store XRES * together with the received SUCI or SUPI. AUSF may also store it in KAUSF for other uses.
[0108] S34, AUSF creates 5G AV: HXRES* is derived from XRES*, and the derived HXRES* is used to replace XRES* in 5G HEAV (RAND, AUTN, XRES*) to obtain 5G AV (RAND, AUTN, HXRES*);
[0109] In S35, the AUSF sends a Nausf_UEAuthentication_Authenticate response message to the SEAF, carrying 5G AV (RAND, AUTN, HXRES*); Note: As can be seen from S34 and S35, XRES* will not leave the authentication center of the home network. The home network further derives XRES* from these two parameters for use by the SEAF;
[0110] S36, SEAF (AMF) initiates the authentication process to UE via NAS message Authentication-Request, carrying authentication parameters RAND and AUTN, as well as the parameter ngKSI. UE and AMF use this parameter to identify one or more security context information. UE's ME will transmit the received RAND and AUTN to USIM;
[0111] After receiving RAND and AUTN, S37 and USIM verify the freshness of 5G AV and verify "MAC=XMAC". Once these verifications are successful, USIM calculates the response RES and returns RES, CK, and IK to ME. ME then derives RES* from RES.
[0112] S38, ME needs to check if the AUTN AMF parameter "separation bit" is 1; UE sends a NAS authentication response message to the network, carrying RES*;
[0113] S39. SEAF derives HRES* from RES* sent by UE, and then compares HRES* and HXRES*. If the comparison passes, authentication is considered successful from the perspective of accessing the network.
[0114] S1A and SEAF send a request to the home network authentication center (AUSF), carrying the RES* parameters from the UE and the response SUCI or SUPI.
[0115] The request sent was: Nausf_UEAuthentication_Authenticate;
[0116] After receiving the Nausf_UEAuthentication_Authenticate request, the S1B and home network AUSF first determine whether the AV has expired. If it has expired, authentication is considered to have failed. Otherwise, RES* and XRES* are compared. If they are equal, authentication is considered successful from the home network's perspective.
[0117] S1C and AUSF send a Nausf_UEAuthentication_Authenticate response to SEAF, informing SEAF of the authentication result of this UE in the home network.
[0118] As can be seen from steps S31 to S1C above, authentication vectors MAC / XMAC, RES / XRES, CK, IK, and AK are generated in the UE and UDM / ARPF using the MILENAGE algorithm for the authentication process; the MILENAGE algorithm is implemented using AES-128; RES* / XRES* / HRES* / HXRES* in 5GAKA authentication are the 128 least significant bits of the identifier output by the SHA-256 function.
[0119] Step 2: Secondary Authentication; The 3GPP protocol does not restrict the specific authentication method used for secondary authentication, allowing users to define it themselves, thus possessing strong extensibility. For example, an EAP (Extensible Authentication Protocol) authentication protocol can be used, offering strong extensibility. The corresponding authentication method and cryptographic algorithm are determined by the terminal and AAA (Authentication, Authorization, Accounting). For instance, some users employ quantum super SIM cards for application domain / secondary authentication security in 5G networks. This solution uses radio frequency fingerprinting for terminal secondary authentication identification. The specific implementation method is described in the following radio frequency fingerprint section, including the following sub-steps: Radio frequency fingerprinting for secondary authentication; The radio frequency fingerprint processing module extracts radio frequency fingerprint feature information based on fingerprint training data (i.e., the input IQ data used for training) and compares it with the local terminal's radio frequency fingerprint database information. A successful comparison indicates successful secondary authentication.
[0120] This application also provides a method for implementing SIM card binding in 5G mobile communication, involving a system to prevent the insertion of SIM cards into unauthorized wireless industrial control terminals. The overall solution process is as follows: Figure 7 As shown, it includes the following steps:
[0121] S1: The terminal and core network complete the main authentication process between the terminal SIM card and the core network according to the main authentication protocol specified in the existing 3GPP standard protocol; after the main authentication is completed, the core network instructs the terminal to send radio frequency fingerprint training information. The main authentication process is as follows: Figure 6 As shown, the specific steps include the following:
[0122] S2: The terminal sends training data to the base station for radio frequency fingerprint recognition on the network side;
[0123] S3: The base station obtains the data in S2, extracts the symbol-level IQ data, and sends this data to the core network or its external radio frequency fingerprint processing module.
[0124] S4: The radio frequency fingerprint processing module extracts the radio frequency fingerprint feature information id_ue based on the fingerprint training data and compares it with the radio frequency fingerprint database information of the local terminal. Successful comparison means that the secondary authentication is passed.
[0125] S5: The terminal generates a random number and sends it to the SIM card;
[0126] S6: The SIM card inputs the random number in S5 as PUF challenge information to the PUF processing module. The PUF processing module outputs the PUF response information priv_ue and sends it to the terminal.
[0127] S7: The terminal uses priv_ue as its private key to generate a public key pub_ue and sends the public key pub_ue to the core network. Although the public key does not need to be encrypted, since the primary authentication and secondary authentication processes have been completed, the transmission process is encrypted over the air using cryptographic algorithms such as AES / Zu Chongzhi from the 3GPP standard protocol.
[0128] S8: The core network uses the received terminal public key pub_ue to encrypt the radio frequency fingerprint feature information id_ue, and obtains id_ue*; the core network uses random numbers to generate a private key and public key pair priv_5gc and pub_5gc;
[0129] S9: The core network concatenates id_ue* and pub_5gc and sends them to the terminal. At this time, id_ue is double-protected by the air interface encryption of the AES / Zu Chongzhi cryptographic algorithm of the 3GPP standard protocol, which is encrypted with the public key of the asymmetric encryption algorithm and then encrypted.
[0130] S10: The terminal uses the private key priv_ue to decrypt id_ue* to obtain id_ue; and sends id_ue to the SIM card;
[0131] S11: The SIM card inputs id_ue from S10 as PUF challenge information to the PUF processing module. The PUF processing module outputs PUF response information id_sim as SIM card feature information and sends it to the terminal.
[0132] S12: The terminal uses the received core network public key pub_5gc to encrypt the SIM card feature information id_sim to obtain id_sim*, and sends it to the core network. Similarly, the transmission of id_sim is protected by both asymmetric public key encryption and air interface symmetric stream cipher processing.
[0133] S13: The core network uses the private key priv_5gc to decrypt id_sim* to obtain id_sim;
[0134] S14: The core network verifies id_sim and id_ue in the mapping table database. If the mapping relationship matches, it means that the device and SIM card are bound together, and subsequent application access is allowed. Otherwise, the terminal is disconnected from the network. The mapping relationship table needs to be pre-made in the core network before the use of legitimate terminals and SIM cards.
[0135] S15: After the terminal accesses the application, it fully complies with the 3GPP 5G network standard protocol process to carry out application data transmission through the base station, core network and application network;
[0136] S16: This system can be set with a timeout period. After the timeout period expires, the data channel connection is maintained, and the above steps S2~S15 are repeated, and the relevant keys are updated. If the mapping relationship matches, the connection is maintained. If there is a mismatch, the terminal is disconnected from the network. The length of the timeout period can be set according to the comprehensive evaluation of security requirements and communication efficiency. The asymmetric algorithm key is updated again after the timeout period expires, which can resist quantum computer attacks on asymmetric encryption algorithms to a certain extent.
[0137] Taking an industrial 5G control terminal as an example, this application implements the terminal-side device and network-side device described in the system. The terminal-side device consists of a wireless function processing module (integrating a radio frequency transceiver, baseband processor, and protocol stack chip), a SIM card slot connecting a SIM card, and its interaction processing module (including a PUF processing module circuit and a cryptographic processing chip); the network-side device includes a 5G base station (including an antenna and a signal processor) and a core network server (with an external radio frequency fingerprint processing module FPGA and a network-side cryptographic forwarding module CPU). In a static relationship, the terminal-side SIM card is electrically connected to the wireless module via an SPI interface; the network-side base station is connected to the core network via an optical fiber link, and the radio frequency fingerprint module receives the IQ data bus. The dynamic relationship and method steps are as follows: First, when the terminal starts up, the SIM card interaction processing module obtains the terminal's special identification code (such as a MAC address) from the device firmware as the PUF challenge input; the PUF processing module uses internal circuit random deviations to generate a truly random response sequence, which is used as a private key for temporary encrypted communication and then immediately deleted. The second step involves the terminal sending an access request. The wireless function processing module processes the signal (RF modulation, baseband encoding, protocol encapsulation), and the network-side base station receives the signal and collects the IQ data after analog-to-digital conversion. When the RF fingerprint enable switch is turned on, it instructs the RF fingerprint processing module to distribute an additional IQ data stream. The third step involves the RF fingerprint processing module training the IQ data, extracting RF fingerprint feature values (such as signal amplitude / phase deviation), and comparing them with its internal feature library. If a match is found, secondary authentication is performed, and the feature value is bound as a unique terminal identification code to the chip fingerprint (response information) generated by the SIM card's PUF. The fourth step involves the password and data processing forwarding module using the bound information to encrypt data forwarding with a one-time key, for example, dynamically generating a session key in industrial control command transmission. The benefits include: the PUF private key generation process is controlled within milliseconds, ensuring real-time performance; the RF fingerprint automatically blocks the connection upon authentication failure, improving system security while maintaining low processing latency (within 10ms).
[0138] This application can be used in industrial control systems to deploy wireless terminals in smart factories, preventing equipment tampering, with an expected annual market growth rate exceeding 10%. In smart city infrastructure, such as monitoring terminals, it can effectively prevent SIM card misuse and improve public safety. With the widespread adoption of 5G, in high-risk scenarios such as connected vehicles and medical devices, the system's two-factor authentication mechanism can be expanded to multi-device authentication, potentially generating billions in economic benefits. In terms of technological evolution, combining AI with optimized RF fingerprint training can further improve authentication accuracy and speed.
[0139] Example 2
[0140] This implementation describes the specific implementation process of a 5G terminal SIM card binding system based on radio frequency fingerprinting and PUF on the terminal side, focusing on the integration scheme of the PUF module in the SIM card and the identity authentication interaction mechanism, including:
[0141] 1) Terminal hardware architecture modification: A Physically Unclonable Function (PUF) module is integrated into the traditional SIM card chip. This module uses SRAM PUF or optical PUF technology to generate unique hardware features through the inherent randomness of the semiconductor manufacturing process. The PUF module connects to the SIM card main control chip via an ISO / IEC 7816-3 standard interface and supports challenge-response protocols.
[0142] 2) Radio Frequency Fingerprint Acquisition Stage: When a terminal first joins the network, the network-side base station acquires the terminal's radio frequency fingerprint characteristics (including 12 parameters such as carrier frequency offset, I / Q imbalance, and phase noise) through air interface signals. The core network radio frequency fingerprint processing module extracts a 256-bit feature code as the terminal's unique identification code (Terminal-ID). This process uses a zero-knowledge proof protocol to ensure that the feature code is not stored locally on the terminal.
[0143] 3) PUF Challenge-Response Binding: The network side transmits the Terminal-ID to the terminal via a 5G NAS secure message. The SIM card PUF module receives this value as a challenge input and generates a 512-bit response output (SIM-ID). A time drift compensation algorithm is introduced in the response generation process to ensure the stability of the PUF output (error rate <0.001%). The terminal encrypts the SIM-ID and sends it back to the network-side UDM element, completing the mapping and binding between the Terminal-ID and the SIM-ID.
[0144] 4) Dynamic key generation mechanism: During each authentication, the terminal obtains the latest Terminal-ID from the network side, and the SIM card PUF module generates a temporary session key based on this value.
[0145] - Private key: Generated by SHA-3 hashing the left 256 bits of the PUF response value;
[0146] - Public key: Derived using the elliptic curve cryptography (secp256k1) algorithm;
[0147] The key is cleared immediately after use and is not written to non-volatile memory.
[0148] 5) Two-way authentication process: When a terminal initiates a service request, the network side issues an authentication command containing a random number (Nonce). The terminal signs the Nonce using the private key generated by the current PUF, and simultaneously attaches the latest radio frequency fingerprint (sampling period ≤ 10ms). The core network performs dual verification by comparing the signature validity and the radio frequency fingerprint drift (threshold set at ±3dB). If authentication fails, an abnormal terminal isolation mechanism is triggered.
[0149] 6) Anti-attack design: An active shield and optical sensor are deployed in the SIM card chip to automatically erase PUF configuration parameters when physical intrusion (such as FIB attacks) is detected. The communication bus uses differential Manchester encoding to prevent side-channel timing analysis.
[0150] This implementation method has been experimentally verified. In the 5G URLLC scenario defined by 3GPP, the average time for the complete authentication process is no more than 20 milliseconds, which is about 10% longer than the traditional IMSI authentication. It can resist more than a dozen known security threats, including replay attacks and man-in-the-middle attacks, and the accuracy of cloned terminal identification exceeds 90%.
[0151] Example 3
[0152] This implementation focuses on describing the specific deployment process and interaction of the SIM card binding system based on radio frequency fingerprinting and PUF on the network side, involving the collaborative work of core network functional modules and the dynamic authentication process:
[0153] Step 1, Network-side RF fingerprint acquisition and feature extraction: When a terminal accesses the 5G network for the first time, the base station captures the terminal's RF fingerprint features (such as carrier frequency offset, phase noise, I / Q imbalance, etc.) through the air interface signal and uploads the raw data to the newly added RF fingerprint processing module in the core network; this module uses a deep learning model CNN to reduce the dimensionality and encode the features to generate a terminal special identification code RF-ID of more than 128 bits;
[0154] Step 2, Dynamic PUF Challenge-Response Binding: The core network sends a challenge command containing the RF-ID to the terminal through the AMF network element; after receiving the challenge value, the PUF in the terminal's SIM card generates a response value PUF-ID using the inherent physical characteristics of the hardware (such as SRAM startup state) and sends it back to the core network through an encrypted channel. The UDM network element stores the mapping relationship between the RF-ID and the PUF-ID in the security database to form a dynamic binding record.
[0155] Step 3, Secondary Authentication and Key Generation: At the start of each session, the network requires the terminal to resubmit its current RF fingerprint. The RF fingerprint processing module compares the extracted RF-ID with historical records in real time. If the deviation exceeds a threshold (e.g., <3%), an alarm is triggered. Simultaneously, the core network issues a new challenge value, and the terminal dynamically generates a session private key via PUF. This private key is used only for the current communication and is destroyed immediately after the communication ends.
[0156] Step 4, Anti-attack Hardening Design: Anti-replay attack: The challenge value uses a combination of timestamp and random number, with the validity period controlled in milliseconds; Anti-side-channel attack: The PUF response generation process shields power and clock fluctuations, employing differential logic circuits; Anti-network hijacking: Communication between the core network and the terminal uses a temporary key generated by the PUF for encryption with the national standard SM4.
[0157] Step 5, Fault Recovery Mechanism: When RF fingerprint drift is detected (e.g., during terminal hardware repair), the system initiates a manual review process, requiring the user to re-register the RF-ID / PUF-ID binding relationship after passing multi-factor authentication such as biometrics, to ensure business continuity.
[0158] This implementation deeply couples the "non-storage authentication" of RF fingerprints with the "dynamic key generation" of PUF, achieving more than twice the anti-cloning capability compared to traditional IMSI / IMEI binding (based on the 3GPP TS33.501 test standard).
[0159] Example 4
[0160] This implementation focuses on optimizing SIM card bonding in 5G network edge computing scenarios, and describes the collaborative work and security enhancement of radio frequency fingerprinting and PUF in a distributed core network architecture, including the following steps:
[0161] Step 1. Terminal-side hardware architecture and initialization process: Upon initial network access, the terminal chipset (including the baseband processor) triggers RF fingerprint acquisition: An RF fingerprint feature vector (256 bits in length) is generated using physical layer parameters such as power amplifier nonlinearity characteristics and carrier frequency offset. This vector, after hash compression, serves as a temporary terminal identity code (TTID) and is uploaded to the network-side RF fingerprint processing module (deployed at the edge UPF node) via a secure channel. The PUF module embedded in the SIM card adopts an SRAM-type PUF structure. After the terminal obtains the TTID: - The TTID is divided into four 64-bit challenge codes (Ch1-Ch4). - Each challenge code is input into the PUF to generate a 160-bit response code (R1-R4). - After BCH(160,64) error correction encoding, the codes are concatenated to form a 640-bit SIM identity code (SID).
[0162] Step 2. The edge UPF node of the network side dynamic binding mechanism performs three-level verification: (1) Radio frequency fingerprint verification: Real-time acquisition of terminal signals and pre-stored fingerprint features for DTW algorithm matching (threshold set to 0.92 similarity) (2) Challenge-response verification: The core network security module randomly issues Ch2 and Ch4 variant challenge codes (⊕ timestamp), and the terminal needs to return the correct PUF response within 300ms (3) Dynamic key generation: Before each session, the AMF network element derives a temporary session key K_session=KDF(SID||SQN||RAND) through the PUF response code. The key is valid for one session.
[0163] Step 3. Anti-attack Enhancement Design - Anti-cloning: The RF fingerprint acquisition module integrates environmental noise detection. When a sudden change in signal parameters (such as power fluctuation > 3dB) is detected, secondary authentication is triggered. - Anti-replay: The PUF response code is bound to the base station Cell ID and TAI (Tracking Area Identifier). It needs to be reactivated when used across areas. - Key protection: The private key generation adopts a "circuit breaker mechanism" - three consecutive erroneous responses trigger the SIM card security domain lock.
[0164] Step 4. Performance test data was tested in the URLLC scenario defined by 3GPP (terminal mobile speed 60km / h): - Authentication latency: The average end-to-end authentication latency was reduced from 480ms in the traditional solution to 210ms. - Security improvement: Success rate of defense against 1000 simulated attacks: - Cloning attack defense rate: 100% - Man-in-the-middle attack defense rate: 99.2% - Physical detection attack defense rate: 98.7% - Resource overhead: The terminal adds a module area of 0.18mm² (28nm process), and the power consumption increases by 4.3mW;
[0165] Step 5. Fault Recovery Process When an anomaly is detected (such as unstable PUF response), the system initiates a tiered recovery process: - Level 1: Assisted calibration via RF fingerprint (maximum 3 attempts) - Level 2: Trigger the core network secondary authorization process (requires operator CA certificate signature) - Level 3: Write to the blockchain audit log and trigger the SIM card replacement process;
[0166] The technical solution of this application has broad application prospects in the field of 5G and future mobile communication security, and can significantly improve the security of terminal identity authentication and SIM card binding.
[0167] Although the illustrative embodiments of the present invention have been described above to facilitate understanding by those skilled in the art, it should be understood that the present invention is not limited to the scope of the specific embodiments. Various changes will be apparent to those skilled in the art as long as they fall within the spirit and scope of the invention as defined and established by the appended claims, and all inventions utilizing the inventive concept are protected. Although the present invention has been described herein in conjunction with various embodiments, those skilled in the art can understand and implement other variations of the disclosed embodiments by reviewing the accompanying drawings, disclosure, and description of the drawings during the implementation of the claimed invention. In the specification, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude multiple components. A single processor or other unit can implement several functions listed in the specification. While certain measures are described in different embodiments, this does not mean that these measures cannot be combined to produce good results.
[0168] Although the invention has been described in conjunction with specific features and embodiments, it is obvious that various modifications and combinations can be made therein without departing from the spirit and scope of the invention. Accordingly, this specification and drawings are merely illustrative of the invention and are considered to cover any and all modifications, variations, combinations, or equivalents within the scope of the invention. Clearly, those skilled in the art can make various alterations and modifications to the invention without departing from its spirit and scope. Thus, if such modifications and modifications fall within the scope of the invention and its equivalents, the invention is also intended to include such modifications and modifications.
Claims
1. A SIM card binding security enhancement system integrating radio frequency fingerprint and PUF, used to prevent unauthorized use of SIM cards, characterized in that, This includes terminal-side devices and network-side devices deployed at the air interface of a 5G mobile communication system; Both the terminal-side device and the network-side device include a wireless function processing module, which is used to perform functional processing of the wireless communication protocol stack corresponding to the wireless security communication system, including radio frequency, baseband and upper layer protocol stack processing. The terminal-side device also includes a SIM card and its interaction processing module. The SIM card includes a PUF processing module and a terminal-side password and data processing and forwarding module. After the terminal-side device obtains the terminal's special identification code, the PUF processing module uses the identification code as a challenge input to generate a private key. The private key is regenerated each time and deleted after use. The network-side device includes a base station and a core network, and the core network may be equipped with an internal or external radio frequency fingerprinting module, a network-side cryptography module, and a data processing and forwarding module. The network-side device implements secondary identity authentication for the terminal based on radio frequency fingerprint identity feature information, and binds the terminal's special identity identification code with the SIM card's special identity identification code; The radio frequency fingerprint processing module extracts radio frequency fingerprint feature values based on IQ data, which are used as unique identifiers for secondary authentication. Combined with the special identity recognition code generated by the PUF processing module, it realizes two-factor SIM card binding. The radio frequency fingerprint processing module of the network-side device is used to generate IQ data sampling indication, send it to the wireless function processing module for handshaking, receive IQ data sent by the wireless function processing module, use the IQ data for training to extract the radio frequency fingerprint of the peer device, compare the processing result with the radio frequency fingerprint feature library inside the module, and send the comparison result to the core network or the application server for secondary authentication.
2. The SIM card binding security enhancement system integrating RFID fingerprint and PUF as described in claim 1, characterized in that, The terminal secondary authentication is specifically implemented on the network side by the radio frequency fingerprint processing module based on the radio frequency fingerprint identity feature information; and after the secondary authentication, the password and data processing and forwarding module uses the radio frequency fingerprint identity feature information as a special identity identification code for the terminal in a one-time password form, and does not store the identification code for a long time.
3. The SIM card binding security enhancement system integrating RFID fingerprint and PUF as described in claim 2, characterized in that, The terminal's special identification code is the fingerprint feature information of the SIM card chip.
4. The SIM card binding security enhancement system integrating RFID fingerprint and PUF as described in claim 3, characterized in that, The terminal device also generates a private key through the PUF processing module of the SIM card. The key is regenerated through the PUF each time it is used and deleted after use.
5. The SIM card binding security enhancement system integrating RFID fingerprint and PUF as described in claim 1, characterized in that, After receiving the wireless signal from the other end, the wireless function processing module of the terminal-side device and the network-side device performs the functional processing of the wireless communication protocol stack corresponding to the wireless security communication system, including the processing of radio frequency, baseband and upper layer protocol stack. At the same time, the network side collects the IQ data after analog-to-digital conversion and sends it to the radio frequency fingerprint processing module according to the instruction of the radio frequency fingerprint processing module.
6. The SIM card binding security enhancement system integrating radio frequency fingerprint and PUF as described in claim 1, characterized in that, The secondary authentication uses the radio frequency fingerprint feature value as the unique identification feature information of the terminal bound to the SIM card for corresponding processing.
7. The SIM card binding security enhancement system integrating RFID fingerprint and PUF as described in claim 1, characterized in that, The PUF processing module in the terminal-side device is used to generate a terminal-side private key, using a random number as the PUF challenge information. The PUF processing module obtains the PUF challenge information and generates a true random signal sequence based on the random deviation of the internal circuit characteristics. It outputs PUF response information as the terminal-side private key. The private key is not stored during the process and is regenerated each time it is used. In addition, the PUF processing module generates the chip fingerprint feature information of the SIM card as the unique identification feature information of the SIM card bound to the device.
8. A method for enhancing SIM card binding security by integrating radio frequency fingerprint and PUF using the system described in any of the preceding claims, relying on the terminal side and the network side, characterized in that, Both the terminal side and the network side perform radio frequency, baseband, and upper-layer protocol stack processing; after obtaining the terminal's special identification code, the terminal side uses the identification code as a challenge input to generate a private key, which is regenerated each time and deleted after use; the network side implements secondary identity authentication on the terminal side based on radio frequency fingerprint identity feature information and binds the terminal's special identification code with the SIM card's special identification code. The secondary authentication is specifically implemented on the network side based on radio frequency fingerprint identity feature information; The radio frequency fingerprint processing module of the network-side device is used to generate IQ data sampling indication, send it to the wireless function processing module for handshaking, receive IQ data sent by the wireless function processing module, use the IQ data for training to extract the radio frequency fingerprint of the peer device, compare the processing result with the radio frequency fingerprint feature library inside the module, and send the comparison result to the core network or the application server for secondary authentication. The radio frequency fingerprint feature value is used as the unique identification feature information of the terminal bound to the SIM card for corresponding processing.
9. The method for enhancing security of SIM card binding by integrating radio frequency fingerprint and PUF as described in claim 8, characterized in that, After the secondary authentication, the radio frequency fingerprint identity feature information is used as a special identity identification code for the terminal. The radio frequency fingerprint identity feature information is used in a one-time password format and the identification code is not stored for a long time.
10. The method for enhancing security of SIM card binding by integrating radio frequency fingerprint and PUF according to claim 8, characterized in that, After obtaining the terminal's special identification code, the terminal side uses this special identification code as the challenge information input to the PUF, and the output response information generated by the PUF is used as the SIM card's special identification code; the network side binds the currently generated terminal special identification code and SIM card special identification code through a mapping relationship to achieve device-card binding.
Citation Information
Patent Citations
Equipment authentication method and device, electronic equipment, storage medium and program product
CN118632248A